16:32 #startmeeting 16:32 Meeting started Mon Sep 30 16:32:42 2013 UTC. The chair is jdstrand_. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:32 16:32 Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired 16:32 The meeting agenda can be found at: 16:32 [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:32 [TOPIC] Weekly stand-up report 16:32 I'll go first 16:33 I'm in the happy place this week 16:34 you do indeed look happy 16:34 I'm working on an apaprmor-easyprof-ubuntu upload which should finish out all the policy/reserved vs common policy groups/etc. I'm waiting for bug #1231863 to be fixed before uploading 16:34 bug 1231863 in ubuntu-ui-toolkit (Ubuntu Saucy) "Local Sqlite databases are still created/stored in incorrect location" [Critical,Triaged] https://launchpad.net/bugs/1231863 16:34 heh 16:35 I also am doing stuff with appstore reviews this week-- various updates for recent changes 16:35 including working with SDK team on filing path bugs against apps now that they are fixed 16:36 "now that they are fixed" referes to the path bugs being fixed in the sdk 16:36 \o/ 16:36 but apps are now broken-- so I am going to enumerate them 16:36 also continue various followups on https://bugs.launchpad.net/bugs/+bugs?field.tag=application-confinement bugs 16:37 I have some patch piloting to do 16:37 and think there is a decent chance I might pick up an update this week 16:37 * jdstrand_ crosses fingers 16:37 mdeslaur: you're up 16:37 I'm on triage this week 16:37 I have a short week as I'm off thursday and friday 16:38 I'm about to push out a few USNs 16:38 and I have a bunch more in our PPA that are in the testing phase 16:38 I may get to a couple more before thursday 16:38 that's about it 16:38 sbeattie: you're up 16:38 I'm on apparmor again this week, trying to offload work from jjohansen 16:39 I'm poking at the very early ipc prototype kernel he got me, now that I finally got it booting :/ 16:40 I also need to followup with jdstrand on the hardware apparmor policy proposal he had made earlier. 16:40 and I need to track down why the parser commits broke both my jenkins build and the daily apparmor ppa builds 16:40 uh oh 16:41 I think it's the newly added dependency on libapparmor for the parser build 16:41 (but we don't need to solve that here) 16:41 I think that's it for me; tyhicks, you're up 16:41 oh, yeah likely, sorry 16:42 I'm testing dbus, apparmor, and evince uploads that fix several bugs 16:42 One of the fixes in dbus-daemon looks like it may affect some of the dbus policy in apparmor-easyprof-ubuntu, so I'll need to coordinate w/ jdstrand 16:42 Then I've got an embargoed issue to work on 16:42 Then I've got one more dbus bug to fix (bug #1229280) 16:42 bug 1229280 in dbus (Ubuntu) "Eavesdroppers confined with AppArmor can see all method_return and error messages" [High,Triaged] https://launchpad.net/bugs/1229280 16:43 I think that's it for me 16:43 jjohansen: you're up 16:44 I'll be working on more apparmor IPC mediation this week 16:45 hrmm I think that is about it for me sarnold your up 16:46 jjohansen, oh, i've been looking at your earlier ping 16:46 I'm not sure sarnold is here yet. chrisccoulson feel free to go ahead 16:46 (hello :) 16:46 jjohansen, http://hg.mozilla.org/releases/comm-esr24/rev/16e20df57d08 is what removed the ability to set the Follow-Up header 16:47 anyway 16:47 chrisccoulson: thanks for looking 16:47 this week, i'll hopefully be getting back to my oxide bug / feature list :) 16:47 sarnold: ah, didn't see you come in :) 16:47 jdstrand_: heh, that was me coming in :) sorry. 16:47 no need to be sorry 16:47 we've got pretty good test coverage for the actual API now, although i'm still adding bits (and fixing bugs as I find them) 16:48 i think that's me done 16:48 chrisccoulson: any progress on the nss ftbfs? 16:48 although I guess it's a little late now to get it in saucy 16:49 mdeslaur, oh, i need to get back to that. sorry. i've got my pandaboard all set up here again now so I've got a bit more flexibility with the test environment 16:49 chrisccoulson: cool, thanks 16:50 i planned to roll back some of the recent updates to see when it fails. the main suspects are gcc, binutils and eglibc, which were all updated since the last time it worked 16:51 * mdeslaur rolls dice 16:51 gcc! 16:51 heh 16:52 mdeslaur, it doesn't matter which one it is. they're all doko's packages anyway :) 16:52 that's why i picked them out as suspects ;) 16:52 (just kidding btw) 16:52 heh 16:52 chrisccoulson: did you have more to report? 16:53 hehe 16:53 jdstrand_, no, i'm done 16:53 sarnold: you're up 16:53 I'm on community this week, and have two more MIR audits to finish up, MIR and open-vm-tools; I would very much like to do both of them this week, but Mir is a large and complicated codebase, I may not make enough progress to finish both this week. 16:54 s/MIR and/Mir and/ 16:54 at least the unity-system-compositor was written in idiomatic c++11, which isn't one of my strong languages, so the going was slower than I'd like. 16:55 but hey I'm getting to learn c++11 while I'm at it, and that's fun. :) 16:55 I think that's it for me, jdstrand_ back to you 16:55 :) 16:55 sarnold: you've been redefining the word "fun" again, haven't you? :) 16:55 * jdstrand_ hugs sarnold 16:55 sarnold, want to port chromium to c++11? 16:56 sarnold: when you're done, can you teach me those bits of c++11? 16:56 mdeslaur: he overloaded the fun operator. 16:56 return True; 16:56 mdeslaur: lol :) yes, just operator_fun() { ... } and away you go! 16:56 chrisccoulson: nothanks :) 16:56 heh 16:57 [TOPIC] Highlighted packages 16:57 i really want to be able to use final and override 16:57 http://people.canonical.com/~ubuntu-security/cve/pkg/argyll.html 16:57 http://people.canonical.com/~ubuntu-security/cve/pkg/passenger.html 16:57 http://people.canonical.com/~ubuntu-security/cve/pkg/gridengine.html 16:57 http://people.canonical.com/~ubuntu-security/cve/pkg/salt.html 16:57 http://people.canonical.com/~ubuntu-security/cve/pkg/openswan.html 16:57 The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 16:57 See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:58 [TOPIC] Miscellaneous and Questions 16:58 Does anyone have any other questions or items to discuss? 17:07 mdeslaur, sbeattie, tyhicks, jjohansen, sarnold, ChrisCoulson: thanks 17:07 #endmeeting